Abstract
Medical image classification has been significantly improved by Convolutional Neural Networks (CNN), enabling efficient and accurate diagnosis, especially in detecting brain tumors. Despite their high success rate, AI infrastructure security of deep learning models remains susceptible to adversarial attacks, involving the careful creation of small imperceptible perturbations to the input data that cause the model to produce inaccurate predictions. This research investigates the resilience of a CNN-based brain tumor classification model in the presence of adversarial attack techniques such as the Fast Gradient Sign Method, Projected Gradient Descent, and the Basic Iterative Method. Trained baseline CNN to classify brain MRI images into four different categories: glioma, meningioma, pituitary tumor, and no tumor, attaining a maximum accuracy of 97.92 percent on clean data. After that, the model’s performance was tested against the three adversarial attacks. In addition, adversarial training was employed by incorporating attack-specific adversarial samples during training to improve model robustness against such perturbations. Fast Gradient Sign Method resulted in a significant accuracy drop to 67.62 percent, while Projected Gradient Descent and the Basic Iterative Method led to accuracies of 77.48 percent and 79.71 percent, respectively. Metrics such as precision, recall, PSNR, RMSE, and perturbation distances were evaluated to determine the severity of each attack. The findings indicate that although all attacks compromise the performance of the model, iterative methods like the Basic Iterative Method make attacks less noticeable and more challenging to defend. These findings highlight the need for AI security by adding robust defense mechanisms in medical AI systems, ensuring reliability and safety in real-world healthcare applications.
| Original language | English |
|---|---|
| Pages (from-to) | 52290-52308 |
| Number of pages | 19 |
| Journal | IEEE Access |
| Volume | 14 |
| DOIs | |
| Publication status | Published - 2026 |
All Science Journal Classification (ASJC) codes
- General Computer Science
- General Materials Science
- General Engineering
Fingerprint
Dive into the research topics of 'Quantifying Resilience of CNN-Based Brain Tumor Classification Under FGSM, PGD, and BIM Attacks'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver